═══════════════════════════════════════════════════════════════════════════
  PCI DSS PREGUNTA 33 — PAQUETE DE EVIDENCIA
  Fuentes externas para identificar nuevas vulnerabilidades
═══════════════════════════════════════════════════════════════════════════

PCI DSS Q33 (PCI v4 Req 6.3.1) requiere:
  - Pruebas de fuentes externas FIABLES para identificar nuevas vulns
  - Proceso de evaluación de riesgo + clasificación
  - Ejemplos del proceso aplicado en la vida real

QSA solicitó: Pantallazos de alertas/notificaciones recibidas de
              fuentes externas

═══════════════════════════════════════════════════════════════════════════
ESTADO DE FUENTES (post-hardening 2026-05-27)
═══════════════════════════════════════════════════════════════════════════

AUTOMATIZADAS (push de alertas — sin intervención manual)
  ✓ GitHub Dependabot      → 196 alertas activas (5 critical, 65 high, 112 medium, 14 low)
  ✓ Wazuh vuln-scanner     → 16 CVEs sobre 4 agentes (cde + app pool)
  ✓ DigitalOcean Status    → status.digitalocean.com + email para incidents

SUSCRIPCIONES EMAIL (CISO inbox: bioscenter.com@gmail.com)
  ✓ Wazuh Security Advisories
  ✓ Debian Security Announce
  ✓ Node.js Security
  ✓ NestJS Advisories
  ✓ Kong Gateway Changelog
  ✓ PostgreSQL Security
  ✓ Cilium Security
  ✓ Falco Security
  ✓ CISA Known Exploited Vulnerabilities Catalog (RSS)
  ✓ OSS-Security mailing list

Total: 13 fuentes (3 automatizadas + 10 email)

═══════════════════════════════════════════════════════════════════════════
HALLAZGOS REALES (snapshot 2026-05-27 22:34 UTC)
═══════════════════════════════════════════════════════════════════════════

GitHub Dependabot — Top CVEs críticos:
  CRITICAL CVE-2026-33937  CVSS 9.8  handlebars            JS Injection AST Type Confusion
  CRITICAL CVE-2026-32621  CVSS 9.9  @apollo/query-planner Prototype pollution
  CRITICAL CVE-2026-32621  CVSS 9.9  @apollo/gateway       Prototype pollution
  CRITICAL CVE-2026-32621  CVSS 9.9  @apollo/federation-*  Prototype pollution
  CRITICAL CVE-2026-25896  CVSS 9.3  fast-xml-parser       Entity encoding bypass

Wazuh vuln-scanner — CVEs sobre cde-pool-node-01:
  HIGH     CVE-2024-41996  CVSS 7.5  openssl 3.0.13        DH key validation flaw
  MEDIUM   CVE-2024-2236   CVSS 5.9  libgcrypt20 1.10.3    RSA timing side-channel
  LOW      CVE-2022-3219   CVSS 3.3  gnupg2 2.4.4          DoS via crafted key
  LOW      CVE-2016-2781   CVSS 2.1  coreutils 9.4         chroot --userspec privesc

═══════════════════════════════════════════════════════════════════════════
PROCESO TRA-001 (Targeted Risk Analysis) — FLUJO
═══════════════════════════════════════════════════════════════════════════

1. IDENTIFICATION
   - Source-driven: Dependabot, Wazuh, vendor email, CISA, etc.
   - Inbox dedicado CISO + dashboard alertas

2. TRIAGE (24h SLA)
   - Filter por: severidad + estado open + package en producción
   - CISO marca como "tracked" o "false-positive"

3. CLASSIFICATION (CVSS × Exposure × PCI-Scope)
   - P0 Critical (24h): CVSS≥9.0 + PCI direct + public exposure
   - P0 Critical (48h): CVSS≥9.0 + PCI indirect + public exposure
   - P1 High (7d):  CVSS 7.0-8.9 + PCI direct + public
   - P1 High (14d): CVSS 7.0-8.9 + PCI direct + internal-only
   - P2 Medium (30d/60d): CVSS 4.0-6.9
   - P3 Low (90d): CVSS <4.0
   - SPECIAL: cualquier CVE en CISA Known Exploited → P0

4. DECISION (CTO approve para P0/P1)
   - Patch disponible? → bump version vía Dependabot PR
   - Sin patch? → compensating control + workaround documentado

5. APPLICATION + VERIFICATION
   - Deploy staging → smoke tests → deploy prod → re-scan

═══════════════════════════════════════════════════════════════════════════
CONTENIDO DEL PAQUETE
═══════════════════════════════════════════════════════════════════════════

  00-README.txt                            (este archivo)
  01-dependabot-alerts-summary.txt         Top 10 alertas Dependabot
  02-dependabot-alerts-raw.json            JSON completo de 196 alertas
  03-cves-summary.txt                      47 CVEs únicos críticos+altos
  04-dependabot-config-recommendation.yml  .github/dependabot.yml a commit
  05-external-subscriptions.md             13 fuentes externas documentadas

═══════════════════════════════════════════════════════════════════════════
Fecha de extracción: 2026-05-27
Extraído por: Gabriel Ureña (CTO Fintrixs SAS)
═══════════════════════════════════════════════════════════════════════════
